Direwolf gang posts Turkish and Chilean hospitals on leak site

Direwolf posted hospitals in Istanbul and Santiago in the same minute, part of a coordinated leak batch.

MedRisk Staff
By
2 Min Read

The Direwolf ransomware gang listed two hospitals on its leak site within the same minute on Sunday, part of a coordinated batch that also named a video game publisher and a fintech firm.

Erdem Hospital, a private hospital group based in Istanbul, appears with a 260 GB data-extraction claim. Hospital Clinico Universidad de Chile, the Santiago teaching hospital affiliated with the University of Chile, was posted seconds later. RansomLook timestamps both entries at 17:31 UTC on August 30, and ransomware.live carries the same Discovered date for each.

Neither post includes patient counts or a breakdown of the data types stolen. Erdem’s victim page shows infostealer-related exposure tied to the hospital domain: one compromised employee credential and 15 compromised users, according to Hudson Rock telemetry on the page. The Chilean hospital’s entry is a bare listing.

Direwolf has cycled through healthcare targets all summer, including a UK clinical software supplier and a kidney exchange nonprofit, both already covered on this site. Public teaching hospitals in Chile and private clinics in Turkey handle the same sensitive categories as US providers: patient records, lab results, and insurance identifiers.

No confirmation from either hospital had surfaced at the time of writing, and leak-site listings are unverified until victims or regulators respond. Hospitals on both continents should treat the listings as a prompt to check backups, review remote-access logs, and rehearse incident response, since extortion groups frequently follow a listing with direct contact to the victim.

Share This Article